Where your data goes, and who can reach it.
The questions an IT department asks before buying from a small vendor. Here are the answers — and what we do not yet claim to do.
A dedicated server, not shared space
Your application runs on a server reserved for you, opened with a French host. No pooling with other clients, no shared database.
We always offer to have the server opened in your own name, with the host of your choice — Scaleway, Cloud Temple, OVHcloud. In that case we are only guests: you can revoke our access at any time. Most companies would rather we handle it, and that is fine. But the choice is yours.
Data stays in France
Hosting in data centres located in France, operated under French law. No transfer outside the European Union in the normal operation of the application.
Where a task requires an AI model, we favour European providers. If a more capable model is required, it is called from a European region under European law. This is settled in writing before go-live, not after.
Encryption, access, traceability
Everything travels over HTTPS with HSTS. Authentication secrets are encrypted with AES-256-GCM before being written to the database: a copy of the database yields nothing usable.
Authentication relies on session tokens of which only the fingerprint is stored — stealing the database does not allow session takeover. Two-factor authentication is mandatory, with protection against replay of an intercepted code. Physical security keys (passkeys) are supported.
Sensitive actions are logged and timestamped. Each user can see their latest sign-in and security events in their own space, and the full log for your account can be provided on request.
Backups — and verified restoration
Full nightly database backup, kept for fourteen days, written atomically so an interrupted backup never replaces a valid one.
What matters is not backing up, it is knowing how to restore. The full cycle — backup, restoration into a witness database, table-by-table verification — has been run for real on our own production. A backup that has never been restored is not a backup.
Monitoring and retention
Application health is checked continuously by a probe that actually queries the database. A probe that merely loads a homepage lets a total outage pass unnoticed — we learned that the hard way, and fixed it.
Retention periods are enforced by an automated job, not by good intentions: deletion beyond the stated period, anonymisation of IP addresses in logs beyond twelve months. Every run leaves an auditable trace.
Reversibility
Your data belongs to you. On request, we hand you a complete copy of it, in an open and usable format, at no cost.
If you decide to stop, you leave with your data. It is the first thing to check with any vendor, including us.
What we do not claim
- We are not ISO 27001 certified nor SecNumCloud qualified. Our hosts are; we are not. The distinction matters and we do not hide it.
- The database is not encrypted in full at rest: only authentication secrets are. Full encryption is possible and is decided per project.
- We do not yet have object storage for large files. If your project needs it, that is added — and said beforehand, not midway.
- We do not run external security audits of our own deliverables. If your organisation requires one, we point you to a specialist and submit to it.
A specific question from your IT department?
Send it as is. If we do not know, we will say so — that is more useful than an approximate answer.
Reply within 48 business hours · No commitment · Confidential